7.2
CVSSv2

CVE-2001-0193

Published: 03/05/2001 Updated: 10/10/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 2.2

suse suse linux 6.3

suse suse linux 6.4

suse suse linux 7.0

Vendor Advisories

Styx has reported that the program `man' mistakenly passes malicious strings (ie containing format characters) through routines that were not meant to use them as format strings Since this could cause a segmentation fault and privileges were not dropped it may lead to an exploit for the 'man' user We recommend you upgrade your man-db package im ...

Exploits

source: wwwsecurityfocuscom/bid/2327/info man is the manual page viewing program, available with the Linux Operating System in this implementation It is freely distributed and openly maintained A problem with the man command may allow for the elevation of privileges Due to the handling of format strings by the -l argument of the man c ...